Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-21105

CVE-2026-21105: Android Collection Information Disclosure

CVE-2026-21105 is an information disclosure vulnerability affecting Android Collection in versions prior to 1.0.1.14 on Android 15 and 2.0.02.7 on Android 16. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-21105 Overview

CVE-2026-21105 is an improper access control vulnerability [CWE-284] in the Samsung Collection application on Android devices. The flaw allows a local attacker on the device to access sensitive information that should be restricted by the application's access controls. Samsung disclosed the issue in its September 2026 mobile security update. The vulnerability affects Collection versions prior to 1.0.1.14 on Android 15 and prior to 2.0.02.7 on Android 16.

Critical Impact

A local attacker can read sensitive information exposed by the Collection app without user interaction, undermining data confidentiality on affected Samsung devices.

Affected Products

  • Samsung Collection application prior to 1.0.1.14 on Android 15
  • Samsung Collection application prior to 2.0.02.7 on Android 16
  • Samsung mobile devices running the affected Collection versions

Discovery Timeline

  • 2026-09-09 - CVE-2026-21105 published to NVD
  • 2026-09-10 - Last updated in NVD database
  • September 2026 - Samsung releases fixed Collection versions via Samsung Mobile Security Update

Technical Details for CVE-2026-21105

Vulnerability Analysis

The Collection application enforces insufficient access control on a component or data path that exposes sensitive information. A local process on the device can reach that path and read data intended to be restricted to the application or a privileged caller. The advisory categorizes the weakness as improper access control [CWE-284], meaning the app fails to verify that a caller is authorized before returning protected data.

Exploitation does not require network access or user interaction. It does require code execution on the device, such as a co-resident malicious application. Impact is limited to confidentiality; there is no integrity or availability effect described in the advisory. The condition is fixed in Collection 1.0.1.14 on Android 15 and 2.0.02.7 on Android 16.

Root Cause

The root cause is missing or incomplete authorization checks within the Collection app on requests that return sensitive data. The application trusts callers or accepts requests without validating permissions, package identity, or signature. This class of Android flaw typically appears in exported components, content providers, or intent handlers that skip caller verification.

Attack Vector

The attack vector is local. A malicious app installed on the same device can invoke the vulnerable interface and retrieve sensitive information. No elevated privileges are required. Samsung has not published detailed exploitation mechanics; refer to the Samsung Mobile Security Update for vendor guidance. No public proof-of-concept exploit is available at the time of publication.

Detection Methods for CVE-2026-21105

Indicators of Compromise

  • Installed Collection app versions below 1.0.1.14 on Android 15 or below 2.0.02.7 on Android 16
  • Unexpected third-party applications issuing intents or content-provider queries against the Collection package
  • Anomalous background access to Samsung Collection components by non-system apps

Detection Strategies

  • Inventory Samsung mobile devices and audit installed Collection app versions against the fixed versions
  • Review mobile threat defense telemetry for local inter-process communication targeting the Collection package
  • Correlate app install events with subsequent access attempts to Samsung system apps on the same device

Monitoring Recommendations

  • Enable mobile device management (MDM) reporting on app versions and patch level for the Samsung monthly security update
  • Alert when devices remain below the September 2026 Samsung security patch level after the update window
  • Monitor sideloaded application installations, which increase the risk of a local attacker being present

How to Mitigate CVE-2026-21105

Immediate Actions Required

  • Update the Samsung Collection app to 1.0.1.14 on Android 15 and 2.0.02.7 on Android 16 through the Galaxy Store
  • Apply the September 2026 Samsung mobile security update on all managed devices
  • Restrict sideloading of untrusted applications via MDM policy to reduce local attack surface

Patch Information

Samsung addressed CVE-2026-21105 in Collection versions 1.0.1.14 (Android 15) and 2.0.02.7 (Android 16). Patch details and delivery are documented in the Samsung Mobile Security Update for September 2026. Users should update via the Galaxy Store or accept the vendor-pushed update, and administrators should enforce compliance through their MDM platform.

Workarounds

  • Disable or uninstall the Collection app on devices that cannot be updated immediately, where operationally acceptable
  • Enforce an allowlist of approved applications through MDM to prevent installation of untrusted local apps
  • Require Google Play Protect and Samsung Auto Blocker to remain enabled on managed devices

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.